Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add more notes on security #63

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

TheAssassin
Copy link
Contributor

The README proposes a very unsafe setup. This PR at least documents the problems

CC #62.

The README proposes a very unsafe setup. This PR at least documents the problems

CC probonopd#62.
@TheAssassin
Copy link
Contributor Author

Huh? Seems GitHub updated their ToS and removed that restriction? https://help.github.com/en/github/getting-started-with-github/types-of-github-accounts

Does anyone have some evidence on this? Running multiple bot accounts just adds some setup complexity but greatly increases security, so I would very much appreciate if that rule went away!

@TheAssassin
Copy link
Contributor Author

Hm, no, still there: https://help.github.com/en/github/site-policy/github-terms-of-service

  • You must be a human to create an Account. Accounts registered by "bots" or other automated methods are not permitted. We do permit machine accounts:
  • A machine account is an Account set up by an individual human who accepts the Terms on behalf of the Account, provides a valid email address, and is responsible for its actions. A machine account is used exclusively for performing automated tasks. Multiple users may direct the actions of a machine account, but the owner of the Account is ultimately responsible for the machine's actions. You may maintain no more than one free machine account in addition to your free User Account.
  • One person or legal entity may maintain no more than one free Account (if you choose to control a machine account as well, that's fine, but it can only be used for running a machine).

@TheAssassin
Copy link
Contributor Author

We're not the only ones affected by this issue. That bit is quoted regularly, e.g., in rust-lang/crates.io#849 (comment).

Maybe someone should try to make GitHub change this rule? https://github.com/github/site-policy/blob/master/CONTRIBUTING.md

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant